Menu

Login Control

Login Control defines the behavior of end-user login and sign-up pages, including page layout, account fields, authentication methods, and phone number region code policies. These settings determine whether users can register and log in with email, phone number, or username.

Path: Log in to the RootAuth console → open the target application → click Configuration in the top navigation bar → Application ManagementLogin Control

 

1. General Login Settings

In General Login, you can configure the login/sign-up page layout, automatic login after sign-up, account fields, and phone number region code policies.

1.1 Login and Sign-Up Page

Mode Description
Separate login and sign-up pages Login and sign-up are displayed as separate pages. Users register first and then log in.
Unified login and sign-up page Login and sign-up are handled on one page for a simpler authentication experience.

 

1.2 Automatic Login After Sign-Up

After this option is enabled, users are automatically logged in after successful sign-up and redirected to the login callback URL.

After this option is disabled, users need to return to the login flow manually after signing up.

2. Configure Account Fields

Account fields control which account identifiers users can use for sign-up and login.

Account field Authentication method For login For sign-up Description
Email-email Password Can be enabled Can be enabled Supports email and password login/sign-up.
Email-email Verification code Can be enabled Can be enabled Supports email verification code login/sign-up.
Phone-phone Password Can be enabled Can be enabled Supports phone number and password login/sign-up.
Phone-phone Verification code Can be enabled Can be enabled Supports phone number verification code login/sign-up.
Username-username Password Can be enabled Can be enabled Supports username and password login/sign-up.

 

2.1 Selection Rules

  • If For sign-up is enabled for an account field, RootAuth automatically enables the corresponding For login option.
  • When sign-up is enabled, login cannot be disabled separately.
  • You can enable For login only without enabling For sign-up. This is useful when existing users can log in with the field, but new users cannot register with it.

 

3. Phone Number Region Code Policy

When phone-number-related login or sign-up is enabled, you can configure the region code policy.

Setting Default Description
Allowed sign-up/binding region codes +86 China Users can only select these region codes when signing up or binding a phone number in user details.
Allowed login region codes Global Users can only select these region codes when logging in with a phone number.

Multiple region codes can be selected. Options include +86 China, +852 Hong Kong, China, +853 Macao, China, +886 Taiwan, China, and Global.

If the sign-up region code policy and login region code policy are different, and the unified login/sign-up page is used, the page follows the Allowed login region codes policy.

When a user uses SMS MFA for the first time and needs to bind a phone number, the phone number region code also follows the Allowed login region codes policy.

All changes take effect only after you click Save at the bottom of the page.

 

4. How Users Sign Up

If both email sign-up and phone sign-up are enabled, the sign-up page displays two tabs: Email Sign-Up and Phone Sign-Up. Email Sign-Up is selected by default.

The phone sign-up page displays:

  1. Phone number field and region code dropdown.
  2. Get verification code button.
  3. Activation code field.
  4. Password field.

If only phone sign-up is enabled, the sign-up page displays only the phone sign-up form without tabs. If only email sign-up is enabled, the page keeps the email sign-up experience.

 

5. How Users Log In

If both email password login and phone password login are enabled, the account label on the password login page is displayed as Email or phone number, and the placeholder is Enter email/phone number.

If only phone password login is enabled, the account label is displayed as Phone number, and the placeholder is Enter phone number.

When users log in with a phone number, the region code dropdown follows the Allowed login region codes configuration.

 

6. Phone Number Uniqueness Rules

Phone numbers are unique within the current application. After a user binds a phone number, they can use that phone number as an account alias to log in.

Keep the following rules in mind:

  1. A phone number that has already been bound cannot be used to register again.
  2. A phone number already used by another account cannot be bound to the current user.
  3. An email address already used by another account cannot be bound to the current phone-number account.

If the phone number or email already exists, RootAuth shows the corresponding duplicate-field message.

 

7. Preview Sign-Up/Login

After completing the configuration, click Preview Login/Sign-Up in the upper-right corner to preview the login and sign-up pages of the current application.

The preview page follows these settings:

  1. Page layout, account fields, authentication methods, and region code policies in Login Control.
  2. Logo and application name in Application Configuration.
  3. Registration security policies in Security Settings.
  4. Authorization mode in Protocol Configuration.

After application settings are changed, they may take up to 2 minutes to take effect on both the preview page and end-user pages.

 

8. View User Records

After users sign up with a phone number, log in with a phone number, or bind a phone number, administrators can go to User ManagementUsers to view the records.

The user list displays the phone number field. Click the phone number or user record to open the user details page and view basic information and bound MFA methods.

 

9. Logs

RootAuth records user authentication events in Audit LogsUser Behavior Logs.

Event type Description
Phone sign-up The user signs up with a phone number.
Phone login The user logs in with a phone number.
Email verification code sign-up The user signs up with an email verification code on the unified login/sign-up page.
Secondary authentication - SMS The user completes MFA secondary authentication with an SMS verification code.

Existing authentication events for email, Google, Telegram, Facebook, and other methods continue to be recorded.

Previous
Protocol Configuration
Next
Authentication Configuration
Last modified: 2026-06-09Powered by